Develop,maintain,andcontinuouslyimprovetheIncidentResponsePlan(IRP)anddetailedplaybooksforarangeofthreatscenarios,includingransomware,phishing,insiderthreat,andthird‑partyincidents,ensuringalignmentwithevolvingattackmethodsandregulatoryrequirements. ConductPost‑IncidentReviews(Post‑Mortems)toassessrootcause,responseeffectiveness,andcontrolgaps,drivingcontinuousimprovementofsecurityposture,policies,andprocesses.